Why modern breaches occur despite alerts – and how post-initial-access detection closes the gap
Most major breaches don’t happen because attackers were invisible. They happen because early signals were misread, deprioritized, or closed too soon.
In today’s environments, attackers increasingly rely on legitimate operating system behavior and trusted tools that blend into normal activity, making malicious actions difficult to distinguish from routine operations.
This paper examines why modern detection fails, how attackers exploit trusted behavior and alert fatigue, and why understanding intent and attack progression is now essential to preventing the breaches that matter most.
We analyze how alert noise, investigation time pressure, and fragmented telemetry contribute to missed attacker progression, using real-world incidents such as the Capita breach and the HSE ransomware attack as illustrative examples. We also outline how post-initial-access behavioral analysis and alert oversight can improve decision quality and reduce the risk of material breaches – without increasing alert volume.
Why Modern Attacks Continue to Succeed
Enterprise security teams today collect vast amounts of endpoint and security telemetry. However, the presence of data and alerts does not automatically translate into effective detection. Many modern breaches progress because:
- Adversaries increasingly exploit legitimate, trusted operating system functionality, causing malicious actions to appear benign in isolation.
- Alerts generated during early attack stages are often low severity, noisy, or lack sufficient context, leading to premature closure or deprioritization.
- Novel or previously unseen tactics, techniques, and procedures (TTPs) are frequently missed due to reliance on prior knowledge, signatures, or trained models.
As a result, attacker activity can persist within environments despite existing alerts and telemetry.
The underlying risk is not invisibility – it is misinterpretation.
For enterprises and managed service providers, the operational impact is significant. Breaches often occur after alerts were generated, but before risk was accurately assessed. This leads to increased dwell time, higher remediation costs, regulatory exposure, reputational damage, and customer churn – particularly in outsourced security and managed detection models.
Why Modern Attacks Are So Easy to Miss
1. Not Every Alert Is Investigated
According to Forrester Research, security operations teams face extreme alert overload. The average SOC receives approximately 11,000 alerts per day.
- Only about 18% are manually reviewed
- Approximately 28% are ignored entirely
- Roughly 32% are false positives, contributing significantly to alert noise
Nearly 50% of SOC managers admit their teams cannot investigate every alert.
2. Detection Is Event-Focused, Not Progression-Focused
Traditional EDR and security tools evaluate individual events – files, processes, hashes, and behaviors – often in isolation. While effective against known threats, this approach struggles when attacks unfold as a sequence of legitimate-looking actions.
Modern attackers rarely trigger a single “smoking gun” alert. Instead, they rely on:
- Built-in OS tools (living-off-the-land)
- Trusted binaries and signed components
- Gradual escalation across multiple stages
Each step appears acceptable on its own. The risk only becomes clear when the sequence is viewed as a whole.
3. AI-Generated and LOTL Attacks Blend Into Normal Activity
AI-assisted malware and novel attack techniques increasingly mimic legitimate workflows. Commands execute correctly. Processes behave as expected. Files appear trusted.
From a traditional detection standpoint, these actions look normal – because individually, they are. This allows attackers to operate below alert thresholds, avoiding escalation while continuing to advance.
4. Alert Noise Drives Deprioritization
SOC teams operate under constant pressure. Thousands of alerts compete for attention, forcing analysts to prioritize based on severity labels, prior experience, and time constraints.
As a result:
- Low-severity alerts are often closed without deeper review
- Alerts lacking immediate context are deprioritized
- Investigation time is compressed to meet operational SLAs
This creates a dangerous condition: false confidence during an active attack.
5. Unknown Tactics Have No Signature
Signature- and ML-based detection relies on prior knowledge. When attackers introduce new procedures, AI-generated variants, or unconventional sequences, detection quality drops sharply.
What cannot be classified is often ignored.
When Missed Signals Become Material Risk – The Capita Case
The 2023 cyberattack on Capita illustrates the real-world consequences of missed or misinterpreted signals.
As reported by The Guardian, Capita was later fined for data protection failings following the breach, which exposed sensitive personal data and disrupted operations. Regulatory findings highlighted systemic weaknesses in security controls and oversight.
Public reporting suggests that:
- Indicators existed before full impact
- Early warning signs were not escalated effectively
- Attack progression was not identified in time
This was not a failure of logging or tooling. It was a failure of signal interpretation and escalation. The breach unfolded not because there were no alerts – but because the dots were never connected.
The Missing Capability: How CyTwist Insights Addresses the Risk of Missed Alerts
To prevent modern breaches, security teams must answer a different question:
Not “Is this alert suspicious?”
But “Is this activity part of an attack in progress?”
This requires understanding intent, not just events.
The CyTwist Insights Engine was designed to close this exact gap.
Instead of generating more alerts, Insights focuses on oversight, correlation, and correction – ensuring that critical signals are not missed or misclassified.
Correlating Alerts With Low-Level OS Evidence
By analyzing sequences of actions over time, the CyTwist Profiler identifies patterns consistent with attacker behavior. This approach surfaces malicious intent even when individual actions appear benign and existing security tools overlook them.
The Insights engine evaluates existing EDR alerts alongside deep OS-level telemetry and behavioral evidence flagged by the CyTwist Profiler. This enables the system to determine whether an alert – even a low-severity or closed one – may be part of a broader attack vector.
Preventing False Confidence
One of the most dangerous states for any SOC is believing an environment is clean while an attacker is already active.
CyTwist helps Reducing Risk Without Adding Noise by:
- Flagging alerts that should be reopened or escalated immediately
- Highlighting hidden relationships between signals missed by other tools
- Exposing attacker intent before encryption, exfiltration, or impact occurs
Crucially, this is not about flooding analysts with more data.
It is about elevating the right signals, at the right time, with the right context.
Why This Matters Now
As attackers increasingly introduce new techniques and abuse trusted system components, including AI-assisted malware and living-off-the-land activity, the cost of missing a signal continues to rise.
In 2026, the question is no longer whether organizations have alerts, but whether they have the insight to act on the right ones.
The HSE ransomware attack provides another stark example. In May 2021, Ireland’s national health system was crippled by a ransomware attack that shut down nationwide IT systems. Post-incident analysis revealed:
- Initial access via phishing and a weaponized Excel attachment
- Antivirus tools detected malicious activity nearly two weeks earlier but remained in monitor mode
- At least 16 systems had unhandled threats that were not remediated before escalation
Here again, early signals existed. The failure was in correlation, escalation, and confidence.
Conclusion: One Missed Alert Is Enough
Modern breaches are not the result of total blindness.
They occur because signals are missed, misread, or dismissed.
One alert closed too quickly.
One behavior deemed benign.
One sequence never connected.
That is often all it takes.
By shifting detection to intent-driven progression analysis, organizations can dramatically reduce the risk of silent failures – and stop attacks before they become breaches.